Privacy Policy

Last updated: May 2025

Your Privacy Matters

Motor Diligence collects only the information necessary to deliver your requested services. We do not sell your personal data. This policy explains clearly what we collect, how we use it, and the rights you have over your information.

1. Introduction

Motor Diligence ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website (motordiligence.com) or engage with our vehicle due diligence services. Please read this policy carefully. By using our services, you acknowledge that you have read and understood this Privacy Policy. If you disagree with its terms, please discontinue use of our services. This policy was last updated as noted above. We will notify users of material changes by updating the revision date. Continued use of our services following any update constitutes your acceptance of the revised policy.

2. Information We Collect

We collect information in two ways: information you provide directly, and information collected automatically. Information You Provide Directly When you submit a Vehicle Review Request, contact form, or otherwise communicate with us, we may collect: • Full name, email address, and phone number • Current location (city/state) and shipping preferences • Vehicle details: year, make, model, trim, VIN, asking price, and vehicle location • Listing URLs and third-party platform references • Service preferences, timelines, and notes • Files and images you choose to attach (stored securely in our cloud storage) Information Collected Automatically When you visit our website, our servers and third-party tools may collect: • IP address and approximate geographic location • Browser type, version, and operating system • Referring URL and pages visited • Device identifiers and session duration • Interaction data (clicks, scroll depth) for analytics purposes We do not collect payment card data directly; payments, if applicable, are processed by third-party payment providers under their own privacy policies.

3. How We Use Your Information

We use the information we collect for the following purposes: Service Delivery • To receive, process, and fulfill your vehicle due diligence service request • To coordinate with third-party inspection providers on your behalf • To conduct remote listing checks, price monitoring, and availability tracking • To prepare and deliver reports, recommendations, and service updates to you Communications • To respond to your inquiries and requests • To send service-related notifications (e.g., inspection scheduled, report ready, price alert) • To follow up on open or pending requests Service Improvement • To analyze usage patterns and improve our website and service offerings • To identify and resolve technical issues Legal and Compliance • To comply with applicable laws and regulations • To enforce our Terms of Service and protect our legal rights • To prevent fraud, abuse, or unauthorized use of our services We will not use your personal information for purposes materially different from those described above without your prior consent.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, our legal bases for processing your personal data are: • Performance of a Contract: Processing is necessary to fulfill the service you requested. • Legitimate Interests: Processing is in our legitimate business interests (e.g., improving services, preventing fraud), where those interests are not overridden by your rights. • Legal Obligation: Processing is required to comply with applicable laws. • Consent: Where we rely on your consent (e.g., optional marketing), you may withdraw it at any time by contacting us at hello@motordiligence.com.

5. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for marketing purposes. We may share information in the following limited circumstances: Third-Party Inspection Providers To coordinate an inspection, we share relevant vehicle details (listing URL, VIN, vehicle location, and inspection preferences) with the independent inspector engaged on your behalf. We share only what is necessary and require that providers handle your information responsibly. Third-Party Transport Providers If you request shipping coordination, relevant vehicle and logistics details may be shared with independent auto transport carriers during the introduction process. Infrastructure and Technology Providers We use Supabase (a PostgreSQL-based backend-as-a-service) to store and process service request data and files. Supabase processes data on our behalf under data processing agreements consistent with applicable privacy law. Our application is hosted via Netlify. AI-assisted listing checks are performed via the Anthropic Claude API; only listing URLs and page content are processed — no personal contact information is transmitted to AI providers. Legal and Safety Disclosures We may disclose information if required to do so by law, subpoena, court order, or regulatory authority; or if we believe in good faith that disclosure is necessary to protect the rights, safety, or property of Motor Diligence, our Clients, or others. Business Transfers In the event of a merger, acquisition, asset sale, or corporate restructuring, your information may be transferred to the successor entity. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

6. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this policy, including to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Specifically: • Service request data (contact details, vehicle information, notes): retained for 3 years following your last interaction with us, then securely deleted or anonymized • Attached files (photos, documents): retained for 12 months following service completion, then deleted from active storage • Analytics and usage data: retained in aggregated, anonymized form indefinitely; identifiable session data is retained for up to 12 months • Communications (emails, notes): retained for 3 years for business record and dispute resolution purposes You may request deletion of your personal data at any time. See Section 9 for how to exercise this right. Note that we may retain certain information as required by law or for legitimate business purposes even after receiving a deletion request.

7. Cookies and Local Storage

Our website uses cookies and browser local storage to support basic functionality, user experience, and analytics. Types of Cookies We Use: • Essential Cookies: Required for the website to function correctly (e.g., session management, form state). These cannot be disabled without affecting site functionality. • Analytics Cookies: Used to understand how visitors interact with our site (e.g., pages visited, time on site). This data is aggregated and not used to identify individual users. • Preference Cookies: Used to remember your settings and preferences for future visits. We do not use advertising cookies or track users across third-party websites for commercial purposes. Local Storage Our React application may use browser local storage to temporarily store form progress and session state. This data is stored solely on your device and is not transmitted to our servers except as part of a form submission. Managing Cookies You may disable cookies at any time through your browser settings. Note that disabling essential cookies may impair your ability to use certain features of our website. You can also use your browser's developer tools to clear local storage at any time.

8. Data Security

We implement technical and organizational measures designed to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These measures include: • Encrypted data transmission (TLS/HTTPS) for all web traffic • Row-Level Security (RLS) policies in our Supabase database, ensuring each record is accessible only to authorized processes • Secure cloud object storage for uploaded files, with access controlled via signed URLs and server-side authorization • API authentication using industry-standard JWT tokens for all service requests • Restricted access to production data, limited to authorized personnel only Despite these precautions, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and any applicable regulatory authority as required by law.

9. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information: All Users • Access: Request a copy of the personal information we hold about you. • Correction: Request that we correct inaccurate or incomplete information. • Deletion: Request that we delete your personal information, subject to legal retention requirements. • Portability: Request your data in a structured, machine-readable format. • Opt-Out of Communications: Unsubscribe from any non-essential communications at any time. EEA / UK Users (GDPR) In addition to the above, you have the right to: • Object to processing based on legitimate interests • Restrict processing in certain circumstances • Lodge a complaint with your local data protection authority California Residents (CCPA / CPRA) You have the right to: • Know what personal information we have collected, disclosed, or sold • Delete your personal information (subject to certain exceptions) • Correct inaccurate personal information • Opt out of the sale or sharing of personal information (we do not sell personal information) • Non-discrimination for exercising your privacy rights To exercise any of these rights, please contact us at hello@motordiligence.com with "Privacy Request" in the subject line. We will respond within 30 days (or sooner if required by applicable law). We may need to verify your identity before processing certain requests.

10. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected personal information from a person under 18, we will take steps to delete that information promptly. If you believe we have collected information from a minor, please contact us at hello@motordiligence.com.

11. International Data Transfers

Motor Diligence is based in the United States. If you access our services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. For users in the EEA or UK, where we transfer personal data outside the EEA/UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or reliance on adequacy decisions, to protect your information in accordance with applicable law.

12. Third-Party Services

Our website and services integrate with the following third-party providers. Each operates under its own privacy policy: • Supabase (supabase.com) — Database, authentication, and file storage • Netlify (netlify.com) — Web application hosting and deployment • Anthropic (anthropic.com) — AI-assisted listing analysis (Claude API); only listing content is processed, not personal data • Resend (resend.com) — Transactional email delivery for service notifications We encourage you to review the privacy policies of any third-party services you interact with through our platform. Motor Diligence is not responsible for the privacy practices of third-party providers.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes, we may provide additional notice via email or a prominent notice on our website. We encourage you to review this policy periodically to stay informed about how we protect your information.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: Motor Diligence hello@motordiligence.com We are committed to working with you to resolve any privacy concerns promptly and fairly.